Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Duke.5200

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:37.39076034Z 53 PC: 1311a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:37.39331853Z 53 PC: 1311a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:37.394661041Z 53 PC: 1311a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:37.39587058Z 53 PC: 1311a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:37.397727059Z 53 PC: 1311a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.399308724Z 53 PC: 1311a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.400841493Z 53 PC: 1311a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:37.402594865Z 53 PC: 1311a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:37.404417382Z 53 PC: 1311a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:37.405550567Z 53 PC: 1311a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:37.40665341Z 53 PC: 1311a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:37.408545952Z 53 PC: 1311a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:37.409511566Z 53 PC: 1311a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:37.410445859Z 53 PC: 1311a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:37.411861815Z 53 PC: 1311a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:37.412848654Z 53 PC: 1311a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:37.413806691Z 53 PC: 1311a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:37.415341021Z 53 PC: 1311a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.421816855Z 53 PC: 1311a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:37.422882191Z 37 PC: 1312f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:37.425128369Z 37 PC: 13137 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.426382011Z 37 PC: 1313f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.427171308Z 37 PC: 13147 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.428578402Z 68 PC: 13b1a | I/O control for devices (Set for = '')
2018-12-17T23:11:37.429815471Z 48 PC: 1372b | Get DOS version
2018-12-17T23:11:37.430836197Z 26 PC: 12fc5 | Set disk transfer address
2018-12-17T23:11:37.43286319Z 78 PC: 12fd1 | Find first file
2018-12-17T23:11:37.437344298Z 61 PC: 135dd | Open file (Filename = 'TEST.EXE')
2018-12-17T23:11:37.441371975Z 66 PC: 13c19 | Move file pointer
2018-12-17T23:11:37.442854479Z 66 PC: 13c27 | Move file pointer
2018-12-17T23:11:37.44435176Z 66 PC: 13c35 | Move file pointer
2018-12-17T23:11:37.446341559Z 62 PC: 1362d | Close file
2018-12-17T23:11:37.449147022Z 26 PC: 12fe9 | Set disk transfer address
2018-12-17T23:11:37.450334546Z 79 PC: 12fee | Find next file
2018-12-17T23:11:37.452896422Z 61 PC: 135dd | Open file (Filename = 'TEST.EXE')
2018-12-17T23:11:37.460616003Z 66 PC: 13c19 | Move file pointer
2018-12-17T23:11:37.461951563Z 66 PC: 13c27 | Move file pointer
2018-12-17T23:11:37.463434938Z 66 PC: 13c35 | Move file pointer
2018-12-17T23:11:37.465288964Z 62 PC: 1362d | Close file
2018-12-17T23:11:37.467374709Z 61 PC: 135dd | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:37.474610139Z 66 PC: 13c19 | Move file pointer
2018-12-17T23:11:37.476990041Z 66 PC: 13c27 | Move file pointer
2018-12-17T23:11:37.478911897Z 66 PC: 13c35 | Move file pointer
2018-12-17T23:11:37.481070549Z 62 PC: 1362d | Close file
2018-12-17T23:11:37.484849284Z 64 PC: 13538 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:11:37.486960931Z 37 PC: 13271 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:37.488067486Z 37 PC: 13271 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:37.489387372Z 37 PC: 13271 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:37.490722879Z 37 PC: 13271 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:37.491797478Z 37 PC: 13271 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.492989586Z 37 PC: 13271 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.494655445Z 37 PC: 13271 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:37.495779447Z 37 PC: 13271 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:37.497116945Z 37 PC: 13271 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:37.498971119Z 37 PC: 13271 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:37.500275162Z 37 PC: 13271 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:37.501377111Z 37 PC: 13271 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:37.503164478Z 37 PC: 13271 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:37.504197581Z 37 PC: 13271 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:37.505322355Z 37 PC: 13271 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:37.506943447Z 37 PC: 13271 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:37.50793432Z 37 PC: 13271 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:37.508996211Z 37 PC: 13271 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.511155782Z 37 PC: 13271 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:37.512159704Z 76 PC: 132b0 | Terminate with return code (Return code = '0')